1 hour 21 minutes
Hello, My name's David. Welcome to analyzing attacks.
A couple quick reminders as we get started in lab one. Often times this is overlooked.
So are you saying
memory analysis reveals a ton of details that you may not get from other kinds?
Other announces. So
I highly recommend that you incorporate memory analysis into your incident, handling her to call processes procedures. Now we talked about different tools
as well. When he comes in, every house is. Do you know what some of us were?
Yes, *** imager or captured
right? Like we're good
motility. There's just some of the big ones that we discussed in some of our prior offenses together. Now,
for the purpose of this lab, I want us to look at Red Line as an but capturing an analysis tool because man, yet has Red Line available to you for free online. You can download it and solid in your system for both analysis and also capturing movie
revenge more hands on abortion
of these episodes. Together
we will actually take a look at some of those as well, however, but who would get to that point? We didn't need to cover this scenario in a couple of other tidbits of information. So your scenario on end user called Help Bess and reported that she thinks click on the link
in an email that was fishy.
So the help that's being helped ask said, Mmm
That's contact the Incident Response Team or the Cyber Security Team. But whatever name in there that you're more those used to. So they boarded the ticket over to you and says, You're a member of the incident response team. Your incident, you know, you get it.
So you run. So maybe scans on. It's just a man. Be able to turn up any suspicious heaven.
What would your next steps be?
And I know open purposes the slab, of course, removing directly into memory examination.
There are a ton of different ways you can purchase this. Uh, you could do a long review. If you're utilizing a sim, um,
you could do registry forensic possible. You could do an entire forensic, capture the system and do a forensic examination. Now, couple words caution their log analysis may not show everything that you need.
They could be infected but not communicating. Ah, a lot of malware is set to beacon on. If you're not familiar with that term, Attackers know what us good people are doing. So they craft their mouth where to beacon
and instead of continuously trying to communicate because more noisy and loud
piece of malware is
easier is to figure out that it's there. So you could do a lot of review not seeing any suspicious activity.
So you may write it off, whereas the system is affected in the mouth. Where is designed not to actually communicate for a while
you could miss, um, you could if you have the ability to download the same email with the link and research that link on and then possibly get the malicious link to yourself, she download whatever it was there it was to be downloaded.
Act pretty fantastic. And he could do that as well, because then you get
the suspicious file that you could do an examination with, and
you could do mount where reverse engineering on it. You could, uh, do what we're gonna do. You could actually take that
malicious files that we think is cautious at this point on. Put it in a virtual machine and no memory catcher and also do other forms of forensic examination on the virtual on the virtual machine that you've infected.
Pretty good standard now these very widely across his inspectors and on the death of team. And your incident wants process. So it's kind of hard and allowed like this actually deal with all those be aware of for this lab. We want to use the Indians Red line. You can find it at the link
located there and also in the lab document that is veiled for you in the course where with Here,
Uh, please download the file on ensure that you have it installed on your system and that it is operating in here is a screen capture to show you what Ren line looked like when you first started up. And we'll take a closer look at this as we proceed.
Bring her into the labs. And don't panic at this point.
Um, when you're getting installed, we'll take care of that when we get to it. Now,
do you get a good mouth where sample? They're all con, different places online that you can go to for the purpose of this lab. We I went thio Now air traffic analysis dot net on downloaded one of newest ones that they have their the links for you there on the screen as well. Also, the
then the lamb document that you can actually go out and refer to as well,
Now we're caution here. This is
live mala ware.
Treat it as such. If you do do this lab and follow through with that ensure you're properly protected and take precautions to not, in fact, your own machine.
I slowed down to say that because you have to be terrible year. Danger, danger, Danger.
Use the windows vm to do your analysis. Don't fire this piece of malware awful in your home system Were inside that work or anything like that because its riel Mauer, I know you're probably sitting there rolling your eyes,
drumming your fingers on the task. Why's he continuing to repeat this? Well, I have to because
we're human and we make mistakes. I make mistakes, you make mistakes. It's a good side of you. Admit that you make mistakes because we are dealing with actually really true malicious files. I feel the need to stress to you that you don't want to infect your system now. Why is that? Ah,
because when I downloaded this on my
my windows defender instantaneously fired off alert and said, Hey,
threat found threat bound. Warning. Warning, Warning. Remember the little robot back there?
Here it is. Now, depending upon what kind of anti buyers or anti Mauer that you're running on your system, you can either shut it off, get it downloaded and transferred over to your B m, or you can allow it to be present on your system. Whatever you do, though,
don't double click this on your home system. Were in your in our environment, what corporate or home? Because
it's really all. So Please, please be careful with this stuff again. Few more words of caution before we dig it. Always remember the malware is dangerous. It's like a box of dynamite.
It could go off. And if it goes off, you could infect your system, resulting you happen to reinstall your operating system, do a cleanse and all that. Now you want to use of'em to experiment, utilize schools and in a lot of our forces here on Sai Berry, there are
references to virtual machines for the purpose of this lab. We're not going to del too deep into it, But you do need to intrude the juvie. Emma's properly said minute and able to communicate with you. You're not more covert network. It's kind of standing step, but you need to remind you of it.
As you go past this course experiment with other pieces of malware, different tools, volatility, FBK damage. To enhance your ability to conduct memory now lists
this lab is not the end all be all memory analysis. I just want you to know that up front is one tool and one piece of Mauer. So you're you're going to learn more. As you experiment with different pieces of malware.
Most of your online repositories would use the password of ineffective, as you can see there on the screen. So put that in your memory hole somewhere is that you don't forget it. If you attended other courses where they use other passwords,
he had in mind also, But on the site that we are going to get this particular consider Matt where the password is infected in. You do need to know that and remember it because unzip the file of extracting now where from it, you need to know what the password is or
you'll quickly we're frustrated,
not be able to follow along if you have any questions as we get prepped here to jump into this, Lamb rejected me. David's 135 on Cyber. Happy to talk to you. Let's keep going.
Identifying Web Attacks Through Logs
Log analysis involves reviewing and evaluating system activities to help mitigate risks. If you’re training ...
3 CEU/CPE Hours Available
Certificate of Completion Offered
Attacks and Persistence for Incident Handlers
Hone your incident handling skills by joining Ken Underhill in this Attacks and Persistence for ...
1 CEU/CPE Hours Available
Certificate of Completion Offered